ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.

A new report indicates that threat actors are employing a novel technique, dubbed "WordlistLoader," to obfuscate malware delivery, specifically targeting campaigns that resemble "ClickFix" operations. This method reportedly disguises malicious payloads as ordinary text files, making them more difficult for security systems to detect and analyze. The primary payload identified in these campaigns is Amatera, an information-stealing malware that has seen a rise in prevalence.
The technical mechanism behind WordlistLoader involves embedding executable code within what appears to be a benign wordlist or similar text-based data file. This approach leverages the fact that many security solutions are optimized to scan for traditional executable formats or common script types, potentially overlooking files that masquerade as inert data. By presenting the malicious content in a format typically associated with dictionaries, configuration files, or other non-executable data, the threat actors aim to bypass initial layers of defense that might otherwise flag suspicious binaries or scripts.
Once the disguised file is executed or processed by a vulnerable system, the embedded malicious code is extracted and run. This typically involves a loader component that interprets the "wordlist" as a sequence of instructions or data to reconstruct the Amatera infostealer. The infostealer itself is designed to exfiltrate sensitive information from compromised systems, which can include credentials, financial data, and other personal or corporate secrets.
The campaigns utilizing WordlistLoader are described as "ClickFix-style," suggesting they likely involve social engineering tactics to trick users into interacting with the malicious files. This class of attack often relies on enticing users to click on malicious links, open tainted attachments, or visit compromised websites, where the disguised wordlist file might be downloaded or presented as a legitimate resource.
The scope of such campaigns can be broad, as social engineering attacks are not typically confined to specific industries or user groups. Any individual or organization susceptible to phishing or similar lures could potentially be targeted. Mitigation for this class of issue typically involves a multi-layered security approach, including robust email and web filtering, endpoint detection and response (EDR) solutions, and user awareness training to recognize and avoid social engineering attempts.
Organizations should also implement application whitelisting where feasible, to prevent unauthorized executables from running, and ensure that security software is configured to perform deep analysis on all downloaded files, regardless of their apparent file type. Regular patching and updates for operating systems and applications are also critical to address any vulnerabilities that might be exploited in the initial stages of such an attack.
The emergence of WordlistLoader highlights an ongoing trend where threat actors continuously innovate their evasion techniques to bypass evolving security defenses. By camouflaging malware as innocuous data, these actors aim to exploit blind spots in detection logic, underscoring the need for adaptive and comprehensive security strategies that go beyond signature-based detection to include behavioral analysis and robust threat intelligence.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed